QID 378742
QID 378742: Splunk Enterprise Resource Description Format Site Summary (RSS) Vulnerability (SVD-2023-0201)
In Splunk Enterprise versions below 8.1.13 and 8.2.10, the createrss external search command overwrites existing Resource Description Format Site Summary (RSS) feeds without verifying permissions. This feature has been deprecated and disabled by default.
CVE-2023-22931.
Affected Versions:
Splunk Enterprise versions from 8.1.0 prior to 8.1.12
Splunk Enterprise versions from 8.2.0 prior to 8.2.9
QID Detection Logic (Authenticated)
Linux: Checks for installed vulnerable version of Splunk Enterprise from "/etc/splunk.version" file either in "/opt/splunk" directory or using "$SPLUNK_HOME" environment variable along with splunk web configuration check using "/etc/system/default/limit.conf" or "/etc/system/local/limit.conf".
Successful exploitation may lead to attacks against RSS software itself, and attacks that use RSS to distribute malicious code to browsers and mail readers.
- SVD-2023-0201 -
advisory.splunk.com/advisories/SVD-2023-0201
CVEs related to QID 378742
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| SVD-2023-0201 |
|